安全扫描
OpenClaw
安全
medium confidenceNULL
评估建议
This skill is coherent for automating image generation via your ChatGPT browser session, but it requires installing and trusting a Chrome extension that will control an actual logged-in browser tab. Before using: 1) Verify the extension is legitimate (publisher, Web Store listing, permissions, reviews). 2) Prefer installing the extension in a separate browser profile with only the ChatGPT account signed in to limit exposure. 3) Do not keep sensitive data or other logged-in accounts in that profi...详细分析 ▾
✓ 用途与能力
Name and description match the instructions: the skill is an instruction-only guide for using OpenClaw's browser automation to generate images via ChatGPT/DALL·E in a logged-in browser tab. It does not request unrelated credentials, binaries, or installs in the manifest.
ℹ 指令范围
SKILL.md instructs the agent to attach a Chrome extension to an already-logged-in ChatGPT tab and then use direct browser control commands (snapshot, click, type, press, screenshot) to drive DALL·E. Those actions are within the declared purpose, but they explicitly rely on controlling your real browser session (including its ChatGPT permissions) and even state 'bypass ChatGPT's bot detection', which has privacy, security, and potential terms-of-service implications.
✓ 安装机制
There is no install spec and no code files; the only installation step documented is a Chrome extension install from the Web Store or the extension bundled with OpenClaw. Because the skill itself does not perform downloads or write to disk, install risk from the skill bundle is low. The real risk is the extension you must trust externally.
✓ 凭证需求
The skill declares no environment variables, credentials, or config paths. It instead instructs use of an already-logged-in browser session; this is proportionate for the stated browser-automation purpose. However, because the extension inherits the browser session, it can access whatever that session has access to—this is a privacy/trust concern rather than a manifest inconsistency.
✓ 持久化与权限
Skill flags are default (not always:true). The skill does not request permanent always-on presence nor modify other skills. It requires the user to attach an extension to a browser tab, which gives the extension session-level privileges, but that is external to the skill's bundle.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/3/4
NULL
● 无害
安装命令
点击复制官方npx clawhub@latest install chatgpt-image-gen
镜像加速npx clawhub@latest install chatgpt-image-gen --registry https://cn.longxiaskill.com